Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Attackers are turning routine business complaints into malware traps. A message about a damaged delivery or refund request can look ordinary, yet one click leads employees to a fake download page and a harmful ZIP archive.

The campaign targeted organizations with Japanese and Korean messages between July and August 2026. Product damage, shipping problems, and exchange requests created urgency, while links appeared to host documents or videos.

Analysts at ITOCHU Cyber & Intelligence Inc. identified the activity and found pages offering Vietnamese, English, Chinese, Japanese, and Korean. Those language choices suggest the operation could extend across East and Southeast Asia.

The impact goes beyond a bad attachment. Victims can receive PureRAT, a remote access tool, or PureLogs, an information stealer. Both pose risks to sensitive business data and give attackers ways to maintain access.

ITOCHU Cyber & Intelligence Inc. said in a report shared with Cyber Security News (CSN) that the campaign repeatedly changed the software used to install its malware. Simple file-based blocking may miss variants, especially when busy teams handle routine customer correspondence.

Turning Business Emails Into Malware Delivery Machines

The lures sound like normal business follow-up. Recipients are told an item arrived damaged, a recording is available, or a refund needs review. The message directs them to a site disguised as a document-sharing or video-viewing service.

The landing page claims a file is too large to preview and asks visitors to download a ZIP archive. Some pages change language using browser settings and location, while mobile visitors see a notice that prevents the download, narrowing exposure to inspection.

Suspicious email (Source - ITOCHUCI)
Suspicious email (Source – ITOCHUCI)

This resembles earlier weaponized archive malware attacks, where an archive hides an executable behind a familiar document name. Here, one sample used a double extension to make an EXE file look like a PDF.

The archives generally pair the executable with a DLL. One sample used a legitimate Microsoft-signed program to load a malicious DLL, which was hidden and padded with unnecessary data.

That extra bulk could frustrate security tools with file-size limits, allowing the infection chain to proceed before alarms reach the security team.

Page displayed on a mobile device (Source - ITOCHUCI)
Page displayed on a mobile device (Source – ITOCHUCI)

Email headers offered clues. The visible sender looked like a support address, but Reply-To pointed to an unrelated Outlook or Hotmail account. Shared identifiers and a common mailer format suggested the messages came from the same delivery environment.

Organizations should verify unexpected refund requests through a separate, trusted channel before opening links. Filters can flag suspicious sharing sites, while staff should report unsolicited complaints that require downloading an archive.

Changing Loaders Hide Data Theft

Once opened, the files launch a layered infection chain. Researchers observed bundled Python software, a modified Donut loader, and code that runs in memory, with each route designed to conceal the final payload.

Variants establish persistence through Startup shortcuts, scheduled tasks, or Registry entries. Others attempt to weaken Windows scanning and logging, while one uses a signed but vulnerable driver to kill security-product processes.

This echoes trusted driver abuse attacks, where attackers exploit high-level system access to silence defenses. Security teams should investigate unexpected driver installations, new services, scheduled tasks, and failed security processes.

PureRAT reports operating-system details, active windows, user names, security products, webcam status, and screenshots to its control server. It can steal information from browsers, cryptocurrency wallets, and messaging applications, making the initial email a gateway to wider exposure.

Malware infection flow (Source - ITOCHUCI)
Malware infection flow (Source – ITOCHUCI)

PureLogs collects browser cookies and profiles, Discord data, screenshots, and file-search results. The final malware remains recognizable across samples, but changing loaders make detection based only on known file hashes unreliable.

Defenders should block the listed indicators, watch for archives containing disguised executables, and review alerts for DLL side-loading and persistence changes.

Recent fake file-sharing phishing campaigns show why trusted-looking portals deserve the same scrutiny as unexpected email attachments.

Combining email checks, behavior monitoring, and quick employee reporting offers stronger protection than any single file signature. A damage claim may be normal business traffic, but a surprise download request deserves closer attention.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps://sharedocumentsystem[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmzncvaret Malicious document-sharing lure
URL hxxps://shareddocumentdrivehub[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmvcznaert Malicious document-sharing lure
URL hxxps://globaldocumentsharingcenter[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/zxczcczlkcjaslda Malicious document-sharing lure
URL hxxps://documentcloudlink[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvcznplrtei Fake video-viewing lure
URL hxxps://drive[.]careernetwork[.]co[.]nz/download.php/Complete_Unboxing_And_Damage_Inspection?f=6d90494c1119bb8cc67a85a9ac9aeaca Malware-download lure
URL hxxps://drbox[.]august-brokers[.]co[.]nz/download.php/Package_Condition_Recordingmp4?f=5331793d7c89907eeff77081d021d10d Malware-download lure
URL hxxps://customerreviewproduct[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJhGfDsAtp Fake video-viewing lure
URL hxxps://customersrespondedpositively[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwXyZatii Fake video-viewing lure
URL hxxps://cloudflare[.]carriernetworks[.]top/?sharingcenterDelivery_Unboxing_Verification.MP4 Fake video-preview lure
IP address 103[.]153[.]74[.]201 Email delivery infrastructure
IP address 103[.]82[.]26[.]183 Email delivery infrastructure
IP address 103[.]82[.]20[.]17 Email delivery infrastructure
IP address 103[.]179[.]189[.]169 Email delivery infrastructure
IP address 103[.]179[.]188[.]9 Email delivery infrastructure
IP address 103[.]179[.]188[.]216 Email delivery infrastructure
IP address 103[.]179[.]188[.]236 Email delivery infrastructure
IP address 103[.]82[.]20[.]60 Email delivery infrastructure
IP address 103[.]153[.]75[.]131 Email delivery infrastructure
File SHA-256 2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d Full_Unboxing_Process_Inspection_Record_2026_1412621.pdf.exe, PureRAT
File SHA-256 e55412555b4699c6d3ce2ac60df81eb1ee0d5aa412a303555c8f64037d5633d0 AppVIsvSubsystems64.dll, PureRAT
File SHA-256 c1a2b48d4f639b46cf6cde8322666f0991531ef32ffe571140418ae40342ffe8 PureRAT payload
File SHA-256 8cd271f946d84423c554992eb0176be395cdd7bf6179efe1822759d019c94f34 Complete_Unboxing_And_Damage_Inspection.exe, Type 1
File SHA-256 eb20fb4e1de2844717270e600af05abac06b359be711eabf14a3d91bfbf966e6 AppVIsvSubsystems32.dll, Type 1
File SHA-256 ad0c3182b18b5d7ba8771d830f4d51b4ada7e26f8d05223f4379e6312aba65fa PureLogs, Type 1
File SHA-256 2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d Full_Unboxing_Process_Inspection_Record_9862_2026.exe, Type 2-1
File SHA-256 9e54486f204d8c9ff9c539c5b2119b79a6da21e3dfdb7f51ee8ebba62f851174 AppVIsvSubsystems64.dll, Type 2-1
File SHA-256 af4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503 PureLogs, Type 2-1 and Type 2-2
File SHA-256 afdb4a8384812e907a73b59df0fb303af2ba94994b5f4bbb66a51ce2b04e7c32 Full_Unboxing_Process_Inspection_Record_9862_2026.exe, Type 2-2
File SHA-256 1b5cf526a28bae9283acf91b2c0ccae3163d24706e40d9a0aea38c4b79e65d36 AppVIsvSubsystems64.dll, Type 2-2
File SHA-256 567fc6e35bb45a6ecf5d870e454c813613032078a5ba01fcd374544930598703 propsys_1f520a24.cache, Type 2-2
File SHA-256 719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0 Delivery_Unboxing_Verification_Details.exe, Type 3
File SHA-256 aee2aefbc73dbf5f65e455ef18e74e158290e21803bf3dd64a05d087bfaceb18 uxtheme.dll, Type 3
File SHA-256 5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946 BootRepair.sys, Type 3
File SHA-256 afd31f096c93776888454e1321654477cfd97eb0c6a75bea624d8f7d891e0a61 PureLogs, Type 3
Domain shareddocumentdrivehub[.]com Malware-delivery infrastructure
Domain globaldocumentsharingcenter[.]com Malware-delivery infrastructure
Domain pixeldrain[.]com File-delivery service observed in campaign
Domain tirakian[.]com PureRAT command-and-control server
Domain logs[.]uvexio[.]com PureLogs command-and-control infrastructure
Domain tea[.]vexexo[.]com PureLogs command-and-control infrastructure
Domain trump2[.]1368[.]lol PureLogs command-and-control infrastructure
Domain bdp[.]edu[.]vn PureLogs command-and-control infrastructure
Domain pure26[.]myftp[.]org PureLogs command-and-control infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines appeared first on Cyber Security News.